CVE-2023-42475: Information Disclosure Vulnerability in Statutory Reporting
Published Oct 10, 2023
·Updated
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
Affected Software
6 affected components
SAP S\/4hana=102
SAP S\/4hana=103
SAP S\/4hana=104
SAP S\/4hana=105
SAP S\/4hana=106
SAP S\/4hana=128
Event History
Oct 10, 2023
CVE Published
via MITRE·01:37 AM
Data Sourced
via MITRE·01:37 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-42475?
The severity of CVE-2023-42475 is medium with a CVSS score of 4.3.
2
How does CVE-2023-42475 impact the confidentiality of the server files?
CVE-2023-42475 enables a low privileged attacker to read server files with minimal impact on confidentiality.
3
Which software versions are affected by CVE-2023-42475?
CVE-2023-42475 affects SAP S/4HANA versions 102, 103, 104, 105, 106, and 128.
4
How can I fix CVE-2023-42475?
To fix CVE-2023-42475, apply the recommended patches provided by SAP and update the affected SAP S/4HANA versions.
5
Where can I find more information about CVE-2023-42475?
You can find more information about CVE-2023-42475 in the SAP Notes 3222121 and the SAP document available at the provided reference links.